Re: [fossil-dev] XSS vulnerability alleged

2018-06-06 Thread Kyle Shannon
On Wed, Jun 6, 2018 at 1:01 PM jungle Boogie wrote: > > On 6 June 2018 at 10:45, Kyle Shannon wrote: > > On Wed, Jun 6, 2018 at 11:44 AM Richard Hipp wrote: > >> > >> On 6/6/18, Kyle Shannon wrote: > >> > Our security team found another XSS, shall I forward the link to the > >> > list? > >> >

Re: [fossil-dev] XSS vulnerability alleged

2018-06-06 Thread jungle Boogie
On 6 June 2018 at 10:45, Kyle Shannon wrote: > On Wed, Jun 6, 2018 at 11:44 AM Richard Hipp wrote: >> >> On 6/6/18, Kyle Shannon wrote: >> > Our security team found another XSS, shall I forward the link to the list? >> >> Yes, please >> -- >> D. Richard Hipp >> d...@sqlite.org > > https://www.fo

Re: [fossil-dev] XSS vulnerability alleged

2018-06-06 Thread Stephan Beal
Jusy fyi, Chrome blocks it with this message: This page isn’t working Chrome detected unusual code on this page and blocked it to protect your personal information (for example, passwords, phone numbers, and credit cards). Try visiting the site's homepage. ERR_BLOCKED_BY_XSS_AUDITOR - stepha

Re: [fossil-dev] XSS vulnerability alleged

2018-06-06 Thread Kyle Shannon
On Wed, Jun 6, 2018 at 11:44 AM Richard Hipp wrote: > > On 6/6/18, Kyle Shannon wrote: > > Our security team found another XSS, shall I forward the link to the list? > > Yes, please > -- > D. Richard Hipp > d...@sqlite.org https://www.fossil-scm.org/index.html/timeline?advm=0&chng=%3C/script%3E%

Re: [fossil-dev] XSS vulnerability alleged

2018-06-06 Thread Richard Hipp
On 6/6/18, Kyle Shannon wrote: > Our security team found another XSS, shall I forward the link to the list? Yes, please -- D. Richard Hipp d...@sqlite.org ___ fossil-dev mailing list fossil-dev@mailinglists.sqlite.org http://mailinglists.sqlite.org/cgi

Re: [fossil-dev] XSS vulnerability alleged

2018-06-06 Thread Kyle Shannon
Our security team found another XSS, shall I forward the link to the list? On Fri, May 12, 2017 at 10:24 AM Richard Hipp wrote: > > On 5/12/17, Kyle Shannon wrote: > > > > Sorry to resurrect an old post, but the site mentioned in the original > > post has disclosed the vulnerability. I was just